---
id: CVE-2023-47246
title: >-
  In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to
  code execution after an attacker writes a file to the Tomcat webroot, as
  exploited in the wild in November 2023.
summary: >-
  In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to
  code execution after an attacker writes a file to the Tomcat webroot, as
  exploited in the wild in November 2023.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: sysaid
product: sysaid
affected:
  - sysaid < 23.3.36
patched:
  - sysaid 23.3.36
published: '2023-11-10'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-47246'
references:
  - url: 'https://documentation.sysaid.com/docs/latest-version-installation-files'
    label: cve@mitre.org
  - url: >-
      https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023
    label: cve@mitre.org
  - url: >-
      https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
    label: cve@mitre.org
  - url: 'https://documentation.sysaid.com/docs/latest-version-installation-files'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-47246
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.98851
epssPercentile: 0.99926
kev: true
kevDateAdded: '2023-11-13'
kevDueDate: '2023-12-04'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-07-31T04:58:34.476Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/W01fh4cker/CVE-2023-47246-EXP'
  nuclei:
    - CVE-2023-47246
  checkedAt: '2026-09-23T07:13:26.087Z'
exploitAvailable: true
---

## Overview

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

## Affected

- `sysaid < 23.3.36`

## Remediation

Upgrade past the affected range:

- `sysaid 23.3.36`
